← Back to app

Privacy Policy

Last updated: June 18, 2026

Pomonotion ("we", "us", or "our") is a productivity application that combines a Pomodoro timer, RPG progress system, and integrations with Google Calendar and Notion. This Privacy Policy explains what data we collect, how we use it, and your rights.

1. Data We Collect

Account information — When you sign in with Google OAuth, we receive your name, email address, and Google account ID from Google. We store this in our authentication provider (Supabase).

Google Calendar data — With your permission, we read and write calendar events so you can schedule Pomodoro blocks. We access only the calendars you choose. We do not store calendar event content on our servers; it is fetched on demand.

Notion data — If you connect Notion, we read your task database to display tasks and write back completion status, points, and scheduled times. Your Notion integration token is stored encrypted (AES-256-GCM) in our database and is never logged or exposed to other users.

RPG progress and app state — We store your XP, stats, streaks, habits, session history, and preferences server-side so they sync across your devices. This data is tied to your account and not shared.

Local storage — The app caches task lists, timer state, and preferences in your browser's localStorage, namespaced to your user ID. This data never leaves your browser except through explicit sync calls to our API.

2. How We Use Your Data

  • To provide the core features of the app: task display, Pomodoro timer, RPG progression, and calendar scheduling.
  • To sync your progress across devices.
  • To authenticate you via Google OAuth.
  • To power AI features (optional): task descriptions may be sent to the Anthropic Claude API to generate suggestions. No personal identifiers are included in these requests.

We do not sell your data, use it for advertising, or share it with third parties except as described below.

3. Third-Party Services

  • Google — OAuth authentication and Google Calendar API. Governed by Google's Privacy Policy.
  • Notion — Task data via Notion API when you connect your workspace. Governed by Notion's Privacy Policy.
  • Supabase — Authentication, database, and row-level-security storage of your account and encrypted credentials. Governed by Supabase's Privacy Policy.
  • Vercel — Hosting and edge functions. Governed by Vercel's Privacy Policy. Vercel KV (Redis) is used for cross-device state sync.
  • Anthropic — Optional AI features (Focus Guardian, task suggestions). Task text may be sent to Anthropic's Claude API. No account data or tokens are included. Governed by Anthropic's Privacy Policy.

4. Data Security

Notion tokens and Google refresh tokens are encrypted with AES-256-GCM before storage. Access to user data is enforced by Supabase row-level security policies — no user can read another user's data. All traffic is encrypted in transit via HTTPS/TLS.

5. Data Retention

We retain your data as long as your account is active. If you delete your account (Settings → Account → Delete account), all your data — including RPG progress, habits, preferences, and encrypted credentials — is permanently deleted from our servers within 30 days.

6. Your Rights

  • Access: You can export all your app data from the Settings panel at any time.
  • Deletion: You can delete your account from Settings → Account.
  • Disconnect integrations: You can disconnect Google Calendar or Notion at any time from Settings. This revokes our stored tokens for those services.
  • Revoke Google access: Visit myaccount.google.com/permissions to revoke Pomonotion's Google access entirely.

7. Children

Pomonotion is not directed at children under 13. We do not knowingly collect data from anyone under 13.

8. Changes to This Policy

We may update this policy as the app evolves. Material changes will be noted on this page with an updated date. Continued use of the app after changes constitutes acceptance of the updated policy.

9. Contact

Questions about this policy? Send us a message and we'll reply by email.